mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 10:55:06 +03:00
debug-167-agent-debugging-blog
5694
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
944c5862f3 |
Chore/small refactors (#47740)
## Context Just extracting the fixes which I think are applicable from this [PR](https://github.com/supabase/supabase/pull/47695) Main files are - `apps/studio/hooks/analytics/useLogsQuery.tsx` - `packages/common/auth.tsx` - `packages/common/feature-flags.tsx` ## Changes involved - Adjust `useLogsQuery` to accept an object as prop, rather than 4 individual params - This one doesn't address any Sentry issues, but is just a improvement to the function's API imo, more readable - Adjust how user email is retrieved in `feature-flags` - Related Sentry issue [here](https://supabase.sentry.io/issues/7592718607/?project=5459134) - The error is a bit vague, but Claude's attempt to fix looks alright in general IMO - Minimally verified that feature flags are loading as expected still <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved log-related screens and queries for more reliable loading and filtering across the app. * Fixed profile and account data handling so identity details are retrieved more consistently. * Improved authentication handling to better recognize missing user data and keep the app stable. * Updated feature flag personalization to use more accurate account information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
982d860123 |
feat(functions): migrate last-hour stats query to OTEL ClickHouse (#47693)
## What Migrates the `edge-functions-last-hour-stats` query (requests + server error counts shown on the Edge Functions list) from the BigQuery-style `logs.all` endpoint to the OTEL/ClickHouse `logs.all.otel` endpoint. <img width="2378" height="958" alt="CleanShot 2026-07-07 at 16 24 43@2x" src="https://github.com/user-attachments/assets/5bf3f04c-43e1-44a3-af28-d53feee27f68" /> ## How - Adds an OTEL SQL builder that reads from the single `logs` table (`source = 'function_edge_logs'`), using `log_attributes['function_id']` and `toInt32OrZero(log_attributes['response.status_code'])` instead of `cross join unnest(metadata)`. - Gated by the `otelLegacyLogs` flag, matching the rest of the logs code. The BigQuery path is preserved when the flag is off, and the two paths cache under separate query keys. ## Testing - Unit tests cover both endpoints and assert the generated SQL for each path. - Go to edge fns list - stats load correctly <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for using the OTEL logs backend for edge function last-hour stats when enabled. * Queries and caching now automatically distinguish between the standard and OTEL-backed data sources. * **Bug Fixes** * Ensured stats results are fetched from the correct endpoint based on the selected logging backend. * Added coverage to verify OTEL-specific SQL and response behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c070893475 |
fix: limit regex (#47717)
- closes https://github.com/supabase/supabase/issues/47712 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved SQL query handling so automatic row limits are no longer added when a query already ends with `LIMIT`, even if there’s whitespace before the semicolon. * Preserved correct behavior for queries using `LIMIT ... OFFSET ...`. * **Tests** * Expanded coverage for SQL limit detection and limit-suffix behavior around whitespace and semicolon placement. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0421b1001d |
Flip show tooltip to true for supavisor connections chart (#47730)
## Context Realised that tooltips were not showing up for supavisor charts in database reports - just needed to flip a boolean Although - i don't have any projects with supavisor connections data (even on prod) so I can't visually verify this atm Also fixes a small issue in which docs url for the chart wasn't showing if the chart had no data, e.g: <img width="996" height="311" alt="image" src="https://github.com/user-attachments/assets/926febe4-9e3d-4975-9278-e7582d6ae12d" /> Should have docs button like this <img width="949" height="351" alt="image" src="https://github.com/user-attachments/assets/7561c1c5-94ae-405b-bd54-6bc94be0dd0a" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Enabled tooltips for the “Shared Pooler (Supavisor) client connections” chart so the metric can be inspected directly. * **UI Improvements** * Adjusted the tooltip positioning in the chart header for clearer readability. * When charts have no data, the “Learn more”/documentation link now follows the provided docs URL. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
62160939a8 |
fix: make status hovercard trigger on focus (#47731)
## Problem Status lists only appear on mouse hover and disappear when panning at 200%+ zoom. ## Solution Make hover-triggered information available via click or focus in line with WCAG 1.4.13 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved keyboard accessibility for the service status hover card by making the trigger focusable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0acc0eb8b3 |
feat: Support Form - Sync AI assistant conversation to Front (#46778)
# Sync AI assistant conversation to Front ## What & why When a user submits a support ticket, an AI assistant chat opens so they get help immediately while waiting for a human agent. This PR mirrors every turn of that chat into the Front conversation the support form already created, so the support team sees the full context and Front automations (routing, emails, CSAT) can act on it. Studio holds no Front credentials — it calls the platform endpoints (see the platform PR) to do the syncing. The assistant card is gated behind the `supportAssistantFollowUp` ConfigCat flag. ## How it works 1. **Submit** — `SupportFormV3` generates a stable `threadRef` (via the `uuid` package — `crypto.randomUUID()` is `undefined` in insecure contexts like non-localhost HTTP and would throw, silently aborting the submit) and sends it on `/platform/feedback/send`. The response returns the Front `conversationId`. Both are stored on `SubmittedSupportRequest`. 2. **Open chat** — `SupportAssistantSuccessCardContent` opens a chat seeded with `supportMetadata` (`threadRef`, `frontConversationId`, subject, category, severity, …). The first message is a `<support>…</support>` XML block. 3. **First user message** — the chat is tagged `isSupportChat = true`; the `onFinish` hook fires `syncSupportChatToFront`. 4. **Subsequent turns** — each `onFinish` slices the unsynced delta, strips the XML metadata block from the seed message, and posts to the platform messages endpoint. 5. **Escalation / resolve** — the `escalate_to_human` / `resolve_support_conversation` tools (and manual **Escalate**/**Resolve** buttons in the assistant input) flip lifecycle status via `setSupportLifecycleStatus` → `syncSupportLifecycleToFront`, which calls the escalation/resolve endpoints. Front rules act on `ai_support_status`. The assistant only resolves after the user explicitly confirms the issue is fixed. ## Key design decisions - **`threadRef` as the shared key** — one UUID travels as `threadRef` on submit and as `chatId` on every sync, so all messages thread into a single Front conversation. - **`conversationId` from the form response** — passed to all sync/lifecycle calls so the platform skips lazy derivation and PATCHes custom fields directly. - **Delta-only sync** — `lastSyncedMessageCount` tracks what's been sent; the boundary is snapshotted before the async call to avoid skipping messages that arrive mid-flight. - **Server-side de-dup** — stable `external_id` (`chatId:msg.id`) means retries don't duplicate in Front. - **Fire-and-forget** — sync failures log to Sentry, never break the chat; `isSyncing` resets on rehydration so the next `onFinish` retries the same delta. Message and lifecycle syncs use separate guards (`isSyncing` / `isLifecycleSyncing`) so an in-flight message sync can't drop an escalate/resolve. - **Lifecycle queued until the conversation exists** — if a lifecycle transition is requested before the initial message sync has returned a `frontConversationId`, it's stored as `pendingLifecycleStatus` and flushed once the id is assigned, rather than dropped. - **Tools return immediately** — the lifecycle tools return a stub to the AI SDK; the real Front call happens in `onFinish`, keeping async I/O out of the tool execute path. - **XML seed stripped before sync** — only the user's actual `<message>` is sent to Front (or dropped entirely if the form already created the conversation). ## Changes | Area | File(s) | | --- | --- | | Support form state | `SupportForm.state.ts` — `threadRef` / `frontConversationId` on `SubmittedSupportRequest` | | Support form submit | `support-ticket-send.ts` — sends `threadRef`, reads `conversationId` | | Support form UI | `SupportFormV3.tsx` — generates `threadRef`, stores `conversationId` | | AI assistant state | `ai-assistant-state.tsx` — `SupportChatMetadata`, `setSupportLifecycleStatus`, `onFinish` wiring, tool handling | | Message sync | `state/ai-chat-front-sync.ts` — delta tracking, message filtering, initial vs. incremental | | API data layer | `data/feedback/ai-chat-front-sync.ts` — typed platform-client wrappers for the three conversation endpoints | | Support tools | `lib/ai/tools/support-tools.ts` — `escalate_to_human`, `resolve_support_conversation` | | Tool integration | `lib/ai/tool-filter.ts`, `tools/index.ts`, `generate-assistant-response.ts` | | Success card | `SupportAssistantSuccessCardContent.tsx` — tags chat on first engagement | | Assistant panel UI | `AIAssistant.tsx` — Escalate/Resolve buttons, disabled input on closed chats, support placeholders | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **New Features** - Support chats now include “Escalate to human” and “Resolve” actions. - Support submissions can be associated with a stable Front thread via a generated `threadRef`, preserving linkage across follow-ups. - AI assistant responses and input hints adapt when support mode is active. - **Bug Fixes** - Improved support chat state management and lifecycle handling to keep conversation metadata and message history synchronized more reliably with Front. - **Chores** - Added/updated coverage to reflect the new support-chat state and syncing behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
0eeeb758d8 |
fix: homepage accessibility fixes (#47729)
## Problem On the organization home page: - you can't tab to a project card and navigate to the project - the status filter popover cannot be open with keyboard - the feedback popover cannot be open with keyboard ## Solution - make the project card (which is a link) accessible with Tab - fix the popover trigger buttons <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved keyboard accessibility so project cards can be focused with Tab navigation. * Updated dropdown and filter popover trigger wiring for more consistent click behavior. * Reset the feedback flow to its starting step whenever the trigger is clicked. * **Bug Fixes** * Made the home icon link explicitly focusable via keyboard navigation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f1c8187d17 |
fix: api docs not found (#47304)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Supabase Studio > Integrations > Data API > [Docs](https://supabase.com/dashboard/project/_/integrations/data_api/docs) ## What is the current behavior? Going to a route that does not exist the user just gets a blank page and no warning. ## What is the new behavior? User now gets redirected back to the intro docs page and and error toast appears ## Additional context Closes #34721 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved handling of invalid Data API documentation links. * If a requested table, view, or function can’t be found after loading, users now see an error message and are redirected back to the main Data API docs page. * This helps prevent blank or broken documentation views when route parameters are incorrect. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
18431efb25 |
fix(studio): TanStack post-merge fixes — Monaco loader, fonts, CSP (from #46424) (#47657)
Post-merge fixes for the TanStack Start migration (#46424) — things that broke on the TanStack build as master evolved under the migration branches. Kept on their own branch off master rather than piling onto the E2E-matrix PR (#47119); all land on master and cascade up to S6 + the big PR. Common theme: a master PR changed something the Next pipeline handles via `next/font` / `pages/_app.tsx` / `next.config.ts`, but the hand-rolled TanStack equivalent (`routes/__root.tsx`, `styles/fonts.css`, `vercel.ts`) wasn't updated to match — invisible on the Next deploy, broken only on TanStack. --- ## 1. Monaco loader path (#47182) #47182 re-nested the served Monaco assets from a flat `public/monaco-editor/` layout into `public/monaco-editor/vs/` and updated `pages/_app.tsx`, but `routes/__root.tsx` still pointed `loader.config` at the old path, so `loader.js` 404'd and **no Monaco editor mounted anywhere in the TanStack build**. Now mirrors the Next config (`${origin}${BASE_PATH}/monaco-editor/vs`, window-guarded for SSR). Was failing the whole `tanstack` E2E shard on #47119. ## 2. Inter + Manrope fonts (#47306) #47306 renamed Tailwind's sans var `--font-custom` → `--font-sans` and added `--font-heading` (Manrope), set via `next/font` on Next. `fonts.css` still only set the now-ignored `--font-custom`, so the body fell back to the theme's system chain (`Circular, custom-font, Helvetica…`) at weight 450 — that's the "Inter weights look wrong". Manrope was missing entirely. - Wire `--font-sans` (Inter) + `--font-heading` (Manrope) to match `next/font`. - **Vendor all three families** (Inter, Manrope, Source Code Pro) via `@font-face` so nothing depends on the Google Fonts CDN — matches `next/font` self-hosting, and (see below) `font-src` doesn't allow `fonts.gstatic.com` anyway. Verified in-browser: computed `body` → `Inter`, headings → `Manrope`, all loading from local `/assets/*.woff2`. ## 3. Security headers / CSP (next.config.ts `headers()`) The Next build sets X-Frame-Options / X-Content-Type-Options / HSTS / **Content-Security-Policy** / Referrer-Policy via `next.config.ts`. The TanStack build never carried these over — `vercel.ts` only set cache-control, so **the deployed TanStack dashboard shipped with no CSP at all**. The TanStack deploy serves a static shell (no server to attach headers), so they go in the Vercel config: - `security-headers.ts` — shared source of truth, reuses `getCSP()`, env-gated exactly like next.config. - `vercel.ts` — apply to every response (all base-path prefixes): full `getCSP()` + HSTS on platform. - `scripts/serve.js` — the non-platform set (`frame-ancestors 'none'`) for the self-hosted server. **Tested the policy in a real browser** (temporarily enforced it on the TanStack build via /test-supabase-local): everything passed except one real gap — `font-src` was missing `data:`, so GraphiQL's bundled Monaco codicon font and Stripe's payment-element fonts (both data: URIs) were blocked (37 violations on a cold load). Added `data:` to `font-src` in `csp.ts` → violations drop to zero, SQL editor Monaco renders clean. That gap affects the Next build too. --- ## 4. `node:path` import crashing `/project/[ref]/merge` Found by a full-site click-through of the TanStack build (all product areas, ongoing — see below). `useEdgeFunctionsDiff.ts` + `EdgeFunctionsDiffPanel.tsx` did `import { basename } from 'path'` in client code. Webpack (Next) polyfills `path` in the browser; Vite externalizes it, so the whole `/merge` route crashed with "Module \"path\" has been externalized for browser compatibility". Replaced the two `basename` call sites with a string helper. Verified in-browser: `/merge` renders. ## 5. URL shape — Next-style search-param semantics + shim fixes The dashboard produced malformed URLs vs the Next build (strange query params, trailing slashes, `##` hashes). Root cause + audit verified empirically against `@tanstack/react-router@1.170.10`; all fixed with unit tests and browser-verified: - **`createRouter` used TanStack's default JSON search codec** — `?flag=true` became `?flag=%22true%22` via links, repeated `?filter=…&filter=…` collapsed into a JSON array (breaking multi-filter/sort table-editor URLs and the account-page round-trip, which double-encoded), and search values arrived as numbers/booleans where the app expects strings. New `lib/router-search-params.ts` (Next-style: strings in, strings out, repeated keys → string[]) wired into the router. - **Link shim** (`compat/next/link.tsx`): `URL.hash` includes the leading `#` while TanStack's `hash` prop adds its own → every `href="…#section"` navigated to `##section` (hash-scroll broke); `Object.fromEntries(searchParams)` dropped repeated query params. Both fixed. - **Trailing slash injected before the query** on every `?`-only relative navigation (`/auth/providers/?provider=…`): fixed in the compat router (prefix current pathname) and via a custom nuqs adapter (`lib/nuqs-tanstack-adapter.tsx`) replacing the stock tanstack-router adapter, whose `navigate({ to: '?…' })` writes hit the same TanStack behavior (123 files use nuqs). - **Pathname-less `router.push({ query })` leaked path params** — Next re-consumes `ref`/`id` from `query` into the path pattern; the shim didn't, yielding `/editor/17597?schema=public&ref=<ref>&id=17597&filter=…` from table-editor filter/sort, linter panels, and advisor shortcuts. The shim now defaults the pathname to the current route pattern and backfills omitted params. - **Redirects dropped query + hash** (Next's `redirects()` preserves them): `__root.tsx` `matchRedirect` and `routes/index.tsx` now carry incoming params/hash through (consumed rule params excluded, destination's own params win). `/?next=new-project&projectName=zzz` → `/new/new-project?projectName=zzz`; `/sql/quickstarts?template=x#frag` → `/sql/examples?template=x#frag`. Browser-verified post-fix: advisors `?preset=WARN`, providers `?provider=Google`, `?schema=auth` — all clean (no `/?`, no leaks); repeated `filter` params survive hydration; `=true` unquoted; single `#`. ## 6. TanStack `navigate` corrupting query values (Logs Explorer SQL newline loss) TanStack router-core treats a query string embedded in `navigate({ to })` as part of the *path*: `decodePath` percent-decodes it and `sanitizePathSegment` strips control characters, silently deleting every `%0A`. Logs Explorer's SQL (`s` param) lost its newlines on Run/reload — `order by timestamp desc` / `limit 5` glued into `desclimit 5`, which then failed the LIMIT lint. Pre-existing on the TanStack build (the stock nuqs adapter had the same shape); Next unaffected. Fixed by never embedding query strings in `to`: the nuqs adapter and the compat `router.push`/`replace`/`prefetch` (plus the `next/navigation` shim) now pass search as an object through the app codec (`splitInternalUrl` hoisted to `lib/internal-url.ts`). Guard test drives a real `createRouter` with multi-line SQL through both producers. Browser-verified: newlines survive the full Run → reload → re-Run cycle. ## 7. Integration overview markdown never loaded (all integrations) `MarkdownContent` used a template-literal dynamic import (``import(`@/static-data/integrations/${id}/overview.md`)``) — webpack builds a context module for that, Vite can't analyze it, so every integration detail page threw `Failed to resolve module specifier` and rendered no overview text. Fixed with an explicit lazy registry of literal imports (`static-data/integrations/overviews.ts`, drift-guarded by a test) plus an `mdRawLoader()` Vite plugin mirroring next.config's turbopack raw-loader rule. Both runtimes keep working; md stays out of the main bundle. ## 8. GraphiQL editor never mounted (`exports is not defined`) Our `umdAmdShortCircuit()` Vite plugin (which disarms Monaco's global AMD loader for deps like papaparse) rewrote `typeof define === 'function' && define.amd` to `false` inside `monaco-editor`'s bundled copy of marked — whose UMD relies on its own *local* `define` shim — so the whole optimized monaco chunk failed to evaluate and GraphiQL's editor pane stayed blank. The check now only short-circuits when `define` is the global AMD loader. Browser-verified: all four GraphiQL Monaco panes mount, queries execute. (Known follow-up: GraphiQL's Monaco workers fall back to the main thread under Vite — functional, worker wiring is Next-specific `setup-workers/webpack`.) ## 9. `@sentry/nextjs` bundling Next internals — built TanStack bundle crashed (caught by E2E) The E2E suite against the **built** TanStack bundle (not the dev server) found lazy chunks like `table-editor-*.js` dead on arrival: `@sentry/nextjs` (imported by ~25 client files) drags in `next/dist/shared/lib/constants`, whose module scope evaluates `process?.features?.typescript` — optional chaining doesn't guard an undeclared `process` in the browser, so the whole chunk failed at load with `ReferenceError: process is not defined`. Dev shims `process`, which is why weeks of dev-server testing never saw it. Fixed by aliasing `@sentry/nextjs` → `compat/sentry-nextjs.ts` (re-exports `@sentry/react`, same deduped 10.59.0, plus explicit stand-ins for the three Next-only APIs) in the Vite build only. Verified: fresh build has zero Next-internals markers in any chunk; table editor loads clean; full E2E suite run against the built bundle. Note for the stack: `alaister/tanstack-start` / the E2E-matrix branch already carried a different fix for the same crash (a `next/constants` shim) that never made it to master — the cherry-pick onto those branches keeps **both** (the shim covers any other transitive importer; the alias keeps Next internals out of the client bundle entirely). **Follow-up found while fixing:** Sentry is never *initialized* in the TanStack runtime — `instrumentation-client.ts` / `sentry.server.config.ts` are Next-convention files nothing imports under TanStack, so `captureException` calls are silent no-ops. Needs an `@sentry/react` init (+ `tanstackRouterBrowserTracingIntegration`) wired into the TanStack client entry as its own PR. ## 10. GraphiQL Monaco workers + edge-function Deno typings (Vite-only gaps) - **GraphiQL's Monaco workers ran on the main thread** under Vite ("Could not create web worker(s)…" — `setup-workers/webpack`'s `new URL(...)` form isn't rewritten by Vite). A `graphiqlViteWorkers()` plugin resolves the import to graphiql's own `setup-workers/vite` variant for client builds (SSR untouched, Next untouched); the setup-workers chain is `optimizeDeps.exclude`d because the Rolldown optimizer can't load `?worker` ids. - **Edge-function editors silently lost their Deno typings** — `AIEditor` loaded `public/deno/*.d.ts` via `/* @vite-ignore */` imports that always failed at runtime under Vite. The `.md` raw loader is generalized into `rawTextLoader` (exact-path allowlist for the two typings files, served as virtual string modules so the dep scanner never parses `.d.ts` syntax), and the imports are now static-analyzable literals that both bundlers handle (turbopack's raw-loader rules match them on the Next side). ## Split out for reviewability App-level fixes that reproduce on the Next build too (DOM-nesting hydration errors, the ghost deleted-snippet nav, the recurring pg-meta `migrations` 400) moved to their own PR: #47667. Sentry initialization for the TanStack runtime (captures were silent no-ops) is #47666, stacked on this PR. ## Full-site test campaign Drove every dashboard product area on the local TanStack build (Playwright, human-style) hunting migration regressions: redirects/404/catch-alls, org, account, project home/branches/merge, table editor CRUD, SQL editor (Monaco/run/save/templates/AI), all database pages, all auth pages, storage CRUD, edge functions + realtime, logs/observability, advisors, settings, integrations hub incl. nested routes, global UI (palette/connect/switchers/theme/fonts), and a cross-cutting sweep (document titles, back/forward chain, hard-refresh hydration on deep URLs, trailing-slash active state). Every failure found is fixed above and re-verified in-browser; remaining console quirks were cross-checked against the deployed Next build and are pre-existing (tracked separately). ## To test Most fixes are already browser-verified + covered by unit tests and the self-hosted E2E suite; the last two landed after the final browser pass and still need an in-browser check: 1. **GraphiQL Monaco workers** — restart the dev server (clear `apps/studio/node_modules/.vite` once first — the optimizer cache may hold a stale prebundle of the worker chain). Open `/project/<ref>/integrations/graphiql/graphiql` with the console open: the `Could not create web worker(s). Falling back to loading web worker code in main thread` warning must be gone, and DevTools → Sources → Threads shows the three workers (json, editor, graphql). Autocomplete in the query editor stays responsive. 2. **Edge-function Deno typings** — `/project/<ref>/functions/new`: no "Failed to load … typings" console error, and typing `Deno.` in the editor offers typed completions (e.g. `Deno.env`). Spot-checks for the rest (all previously verified): - `/project/<ref>/merge` renders (no "Module path" crash). - Multi-line SQL in Logs Explorer survives Run → reload (no `desclimit` gluing, no LIMIT-lint false failure); `s` param keeps `%0A`. - `/auth/providers` → open a provider → `?provider=…` with no trailing slash before `?`; table-editor filter/sort URLs carry no leaked `ref`/`id` params; `/?next=new-project&projectName=x` lands on `/new/new-project?projectName=x`. - Integration detail pages (cron/queues/vault/data_api) show their overview prose; GraphiQL query editor mounts. - Built bundle (`MODE=test vite build` + `start:tanstack`): table editor loads with no `process is not defined`. - `curl -sI` any page on a platform deploy: `X-Content-Type-Options: nosniff` (was the invalid `no-sniff`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Centralized integration overview markdown loading with registry-based lookup. * Improved Monaco loading/asset path handling for smoother editor startup. * **Bug Fixes** * Next-style navigation/search handling now preserves pathname, hash, repeated query keys, and special characters (including newlines). * Redirects now reliably carry over query and hash with correct precedence. * **Security/Configuration** * Updated CSP font sourcing and unified security headers delivery across environments; conditional HSTS behavior. * Refreshed font CSS variables and font-face definitions to match the theme. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- ### Review feedback: non-prod favicon (Joshen) The TanStack `__root.tsx` hardcoded the prod favicon; local + hosted staging now use the white staging favicon (`/favicon/staging`), matching what `pages/_app.tsx` passes to `MetaFaviconsPagesRouter` for non-prod. Rather than pull the pages-router component into the TanStack head, it reuses the same synchronous `NEXT_PUBLIC_ENVIRONMENT` signal the file already uses for `IS_DEV_TOOLBAR_ENABLED` (the `head()` route option isn't a React component, so it can't run `_app`'s async CLI check — but the env signal covers the reported local/staging case). --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
fa20667ec1 |
fix(studio): migrate email template reset dialog to async AlertDialog (#47705)
## What kind of change does this PR introduce? Bug fix / refactor. Resolves DEPR-573. ## What is the current behavior? `ResetTemplateDialog` (added in #45572) confirms the Auth email template reset using the old `AlertDialog` workaround: an `AlertDialogAction` with `asChild` + `event.preventDefault()` and a manual loading `Button`, driven by `mutate` plus inline callbacks. Reset failures are only reported via a toast from the mutation's default `onError`, so the error disappears from the dialog context. This predates #45960, which added first-class async handling to `AlertDialogAction` (promise-returning handlers, controlled `loading`, and `AlertDialogBody` for inline feedback). #45960 explicitly flagged `ResetTemplateDialog` as needing this follow-up migration. ## What is the new behavior? `ResetTemplateDialog` now uses the async `AlertDialogAction` pattern: - The confirm handler uses `mutateAsync` and returns the reset promise, so the dialog stays open with a loading state while the mutation is pending and closes only after it succeeds. - Reset failures surface inline via a destructive `Admonition` inside `AlertDialogBody`, and the mutation's toast-only error path is suppressed (`onError: () => {}`). The inline error clears when the dialog closes. - `Cancel` is disabled while the reset is in flight. - The `asChild` + `preventDefault()` workaround and the manual loading `Button` are removed; `loading={isResetting}` is retained for parent-controlled loading. This matches the established usage in `DisablePipelinesDialog` / `JitDbAccessDeleteDialog` and the design-system `alert-dialog-async-error` example. ## To test - [ ] Customise an Auth email template, click **Reset template**, confirm the dialog shows loading until the reset succeeds and then closes with the editor refreshed to the default subject/body. - [ ] In DevTools → Network, block `*/templates/*/reset`, click **Reset**, and confirm the dialog stays open with an inline destructive admonition and no toast. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved email template reset error handling by showing reset failures inline in the confirmation dialog (with a destructive alert message). * The dialog remains open on reset failure so users can review the error and retry. * “Cancel” is disabled while resetting; success behavior and existing success toast behavior remain unchanged. * **Tests** * Updated reset mutation mock to use async behavior and added coverage for reset failure UI/error handling (including that error toasts are not triggered). <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
511a7806de |
Joshen/fe 3789 unified logs filters click area is too small (#47675)
## Context Increases the click area of unified logs filter ### Before <img width="1070" height="828" alt="image" src="https://github.com/user-attachments/assets/7e2a45de-7844-4feb-accb-fdaecfa1066c" /> ### After <img width="623" height="130" alt="image" src="https://github.com/user-attachments/assets/c8310975-1f2f-42dc-aaff-fdcd112b1bee" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved spacing and alignment in filter checkbox rows. * Adjusted the expand/collapse control and “only” button positioning for a cleaner layout. * Refined nested option connector placement and sizing for better visual consistency. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b10ed73d66 |
Studio light background (#47722)
Overrides bg on Studio just to give a bit more elevation <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the light theme’s surface styling by introducing a new theme value (`--surface`) to improve visual consistency across the app. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9af6e65df4 |
fix(studio): DOM-nesting hydration errors, ghost deleted-snippet nav, and migrations query 400s (#47667)
App-level fixes that reproduce on BOTH the Next and TanStack builds — split out of #47657 (which stays TanStack-only) for reviewability. All were found by a full-site click-through of the dashboard. ## Invalid HTML nesting (React 19 "will cause a hydration error" console errors) - **FormLayout description rendered in a `<p>`** (`packages/ui-patterns`): consumers pass arbitrary JSX (the RowEditor's `created_at` timezone note passes a `<div>` with `<p>`s) → `<p>`-in-`<p>` / `<div>`-in-`<p>`. Container is now a `<div>` with identical classes (Tailwind preflight makes them render the same). - **Switch toggles nested inside Tooltip trigger buttons** (button-in-button) in ColumnEditor ("Allow Nullable" + "Is Unique"), ExtensionRow, and PublicationsTableItem → repo-standard `TooltipTrigger asChild` + `<div>` wrapper. - **Saved log queries rendered a `<div>` directly inside `<tbody>`** (`/logs/explorer/saved`) → rows are now proper `<tr><td colSpan>` wrappers; the component itself is untouched (it's valid in its sidebar usage). - **Nested anchors in observability metric cards**: a card-level `<Link>` wrapped MetricCard's "More information" `<Link>` (identical URLs) → the chevron affordance renders as a `<span>` when no `href` is passed; clicks bubble to the card link, tooltips preserved. Design-system standalone usage unaffected. - **`objectFit="cover"` passed to modern `next/image`** on the featured integration card (unknown-prop warning) — the className already had `object-cover`; prop dropped. ## Ghost dead-snippet after deletion Deleting the active SQL snippet left its id in `useDashboardHistory` (`history.sql`), so the "SQL Editor" nav item navigated to `/sql/<deleted-id>` — content fetch 404s, no editor pane renders, and a phantom tab reappears. Fixed both ends: delete flows now purge dashboard history (and the tabs store clears a stale `previewTabId`), and `/sql/[id]` treats a snippet 404 as "clean up + `router.replace` to `/sql/new` + toast" instead of rendering the dead state. Unit tests for the store/history cleanup. ## `pg-meta` migrations query 400s on every project load `ActivityStats` on project home runs the migrations list query, whose SQL was a bare `select * from supabase_migrations.schema_migrations` — that table only exists once a migration has run, so every other project logged a failed `?key=migrations` request on every load (visible in production consoles too). The SQL is now guarded with `to_regclass` + `query_to_xml` (same pattern as the advisor lints' `storage.buckets` guard), returning zero rows instead of erroring; legacy version-only tables still work. Tested against real dockerized Postgres (absent table, populated ordering, special chars, legacy schema) + MSW hook tests. Found and verified via /test-supabase-local (browser click-through + console audit on both builds). ## To test Console must stay free of React DOM-nesting errors ("cannot be a descendant of" / "cannot contain a nested") on each surface: 1. Table editor → Insert row panel (`created_at` field renders its timezone note) and Edit column panel ("Allow Nullable"/"Is Unique" tooltips still hover). 2. `/database/extensions` and `/database/publications` → toggle switches render, tooltips hover. 3. `/logs/explorer/saved` (with ≥1 saved query) → rows render full-width inside the table, hover shows Actions. 4. `/observability` → no nested-anchor error on load; card body click and the chevron both navigate; label help-icons still show tooltips. 5. `/integrations` → no `objectFit` unknown-prop warning; featured card images still cover. 6. **Ghost snippet**: open a SQL snippet → delete it via the sidebar → click the "SQL Editor" nav item → lands on `/sql/new` (no phantom tab, no 404 content fetch). Direct-load `/sql/<random-uuid>` → toast + redirect to `/sql/new`. 7. **Migrations 400**: load project home with a project that has never run a migration → the `pg-meta/<ref>/query?key=migrations` request returns **200** with `[]` (previously a 400 on every load). Database → Migrations still lists real migrations when they exist. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Bug Fixes** * Deleted SQL snippets are fully removed from dashboard history and stale editor/tab state; users are redirected with a toast. * Closing preview tabs no longer leaves stale references. * Improved toggle/tooltip/dialog interactions to avoid broken UI, including metric headers showing tooltips even without direct links. * Migrations display safely when migration tables/relations are missing. * **UI Improvements** * Refreshed layout for saved queries, form descriptions, and integration imagery. * **Tests** * Added coverage for snippet history cleanup, tab removal, migrations SQL behavior, and query edge cases. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- ### Review feedback: `query_to_xml` breaks on Multigres (Ivan) The defensive migrations query (added here to stop the `?key=migrations` 400 when the table doesn't exist yet) originally guarded with `query_to_xml`, which is forbidden through Multigres's pooler (MUL-736 / PSQL-1318). Rewritten without `query_to_xml`/`xmltable` using the splinter#170 pattern: a PL/pgSQL `do` block guarded by `to_regclass` (PL/pgSQL defers planning, so a missing table never errors) stashes the rows into a transaction-local GUC via `set_config`, and a trailing `select` reads them back with `jsonb_array_elements`. Verified that postgres-meta sends the whole SQL as one simple-query string → single implicit transaction → the local GUC survives to the `select` and doesn't leak into the pooled connection. 6/6 dockerized-Postgres tests (absent table → `[]`, populated/ordered/special-chars, legacy version-only table, full pg-meta-shaped multi-statement string, GUC non-leakage). Note (out of scope, pre-existing): `packages/pg-meta/src/sql/studio/advisor/lints.ts` still uses `query_to_xml` — a separate pre-existing Multigres risk that should get its own splinter-pattern sync. --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Saxon Fletcher <saxonafletcher@gmail.com> |
||
|
|
b3c98c11f8 |
Use Link component instead of native a element in marketplace settings (#47720)
## Context Just a tiny one to use `Link` instead of `a` tags to render links in Marketplace settings The `a` tags would otherwise drop the `/dashboard` URL prefix on staging and prod <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved navigation in the integrations resource group section by using app-native links for management actions, making links behave more consistently across the interface. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5677b0ec2a |
chore(studio): clarify integration settings copy (#47578)
## Summary - Clarifies Vercel integration settings copy for org-scoped and project-scoped contexts. - Updates GitHub and Vercel integration section titles to sentence case for in-page headings. - Contributes to DEPR-565. | Before | After | | --- | --- | | <img width="1242" height="759" alt="Integrations Basket Supabase" src="https://github.com/user-attachments/assets/df33a9d4-8fb3-40cf-87d2-e87fa33195e4" /> | <img width="1150" height="715" alt="Integrations Basket Supabase" src="https://github.com/user-attachments/assets/45478216-c426-4bc1-9292-9a6016ac7af9" /> | | <img width="1242" height="759" alt="18154" src="https://github.com/user-attachments/assets/8dfb7742-fca5-421f-88d0-4d24dad93450" /> | <img width="1150" height="715" alt="Integrations Settings Agua Basket Supabase" src="https://github.com/user-attachments/assets/aa119d0e-cf5e-45e5-b5d3-cd8c0d047e34" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **UI Text Updates** * Updated GitHub and Vercel headings and labels to use consistent casing (e.g., “GitHub connection”, “Vercel”). * Adjusted success and empty-state messaging for GitHub and Vercel integration actions. * **UX Improvements** * Improved GitHub and Vercel section descriptions by tailoring the text to project-scoped vs organization-scoped contexts. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c4c213ce3d |
feat(studio): switch dashboard assistant to remote MCP server (#47479)
## I have read the [CONTRIBUTING.md](<https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md>) file. YES ## What kind of change does this PR introduce? Feature / refactor. ## What is the current behavior? The dashboard assistant runs `@supabase/mcp-server-supabase` in-process over an in-memory transport (`lib/ai/supabase-mcp.ts`). ## What is the new behavior? The assistant connects to the **remote MCP server** over HTTP (`@ai-sdk/mcp`), forwarding the dashboard session token as a bearer. URL comes from `NEXT_PUBLIC_MCP_URL` with a local-dev fallback; platform-only, and Nimbus works via the same env var. * **Tool model unchanged:** UI-controlled `execute_sql` (with `needsApproval`) and `deploy_edge_function` still come from Studio; the allowlist (`TOOL_CATEGORY_MAP`) remains the gate keeping the remote's write tools away from the assistant (`read_only` is defense-in-depth). * **Attribution:** sends `x-source-name: supabase-studio` (+ `x-source-version`) → logged as `source_name`/`client_name`. * **Connection lifecycle:** the HTTP client is closed via the request's `AbortSignal` (tools execute later during streaming); `signal` is required on `getTools`/`getMcpTools`. * **Resilience:** a remote-MCP failure degrades to the remaining tools instead of failing the assistant. * **Drift protection:** relied-upon tools are typed against `keyof typeof supabaseMcpToolSchemas`, so a package bump that renames/removes one fails `pnpm typecheck`; a runtime check also warns if the deployed server returns fewer tools. * Adds unit tests for the above. ## Additional context * Verified end-to-end against a local remote MCP server with a dashboard token: `initialize` 200, tools listed, a tool executed, client closed cleanly. * The remote MCP (mgmt-api) already accepts dashboard session tokens (GoTrue-JWT auth path) — no backend change needed. `NEXT_PUBLIC_MCP_URL` must point at each env's `/mcp`. * `@supabase/mcp-server-supabase` is kept — still used by the self-hosted `/api/mcp` routes. Closes [AI-137](https://linear.app/supabase/issue/AI-137/switch-dashboard-assistant-to-remote-mcp) ## Rollout * **Rollout:** merges with `USE_REMOTE_MCP` off (in-process); flip it to `true` per environment (staging → prod → Nimbus) once each one's prerequisites land. * **Rollback:** unset `USE_REMOTE_MCP` and redeploy to fall back to the in-process client — no revert needed. ## Summary by CodeRabbit * **Bug Fixes** * Improved AI request handling so tool loading and generation clean up properly when a request is cancelled or the browser connection closes. * Added safer fallback behavior when remote tool loading fails, so AI features can continue with available tools instead of stopping entirely. * Updated remote tool access to use the current project reference and preserve the correct access headers. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * AI tools now connect more reliably to remote services and stop cleanly when requests end or are canceled. * Tool loading is more resilient, continuing with available tools if remote access is unavailable. * **Bug Fixes** * Improved cleanup to prevent lingering connections during SQL generation and policy workflows. * Added safer handling for remote tool changes and invalid responses. * **Tests** * Expanded automated coverage for remote tool setup, cancellation, and fallback behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
5dc054ae8f |
feat(studio): warn in Connect sheet when Data API is disabled (#47537)
## What kind of change does this PR introduce? Feature. Resolves DEPR-599. ## What is the current behavior? When the Data API is disabled (PostgREST has no exposed schemas), the Connect sheet still shows client-library setup steps for Framework and MCP modes without indicating that database queries will fail. ## What is the new behavior? When database access via the Connect instructions requires PostgREST, an inline warning appears above the steps (setup instructions remain visible): - **Framework**: warns when Data API is off; install, env vars, and auth/SSR setup still work - **MCP**: warns only when Database tools apply (selected explicitly, or by default when no feature filter is set) The warning fails open if PostgREST config cannot be loaded, and links to Data API settings via an "Enable Data API" CTA. | After | | --- | | <img width="1664" height="718" alt="CleanShot 2026-07-02 at 21 29 16@2x" src="https://github.com/user-attachments/assets/80d21927-c4dd-4158-8946-bf648b95e451" />| ## Additional context - Gating logic lives in `ConnectStepsSection.utils.ts` with unit tests - Out of scope: warning when Data API is on but zero tables/schemas are exposed - Coexists with the upcoming warehouse branch's catalog warning — that lives in a separate `WarehouseCatalogPanel` for `catalog` mode only <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Connection setup now checks Data API enablement and conditionally shows a “Data API disabled” warning, including an action to open Data API settings. * **Bug Fixes** * Warning logic now more accurately reflects the selected connection mode and chosen feature/tool selections. * **Tests** * Added a focused test suite covering the Data API configuration decision rules and when the warning should appear. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
468aeb062e |
fix: add a skip to main content link in default layout (#47694)
## Problem Screen reader and keyboard users have no way to skip the header and sidepanel navbar so they have to manually tab through every items before accessing the actual main page items. ## Solution Add a _Skip to content_ link for them <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a “Skip to content” link to help users jump directly to the main page area. * Updated the main content wrapper to a semantic `main` landmark with an anchor target. * **Accessibility** * Improved keyboard and screen reader navigation by supporting better in-page navigation and landmarks, without changing the page’s visible content. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a6a04f24cd | fix(studio): correct exposed-schema settings for the Data API (#47511) | ||
|
|
a84fd10a4f |
chore: simplify project copy buttons labels (#47689)
## Problem Screen reader users don't need to be told how to use a button: _Press Enter to copy project name_ ## Solution Simplify the button labels: _Copy project name_ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility** * Updated screen-reader text in the dropdown menu so uncopied items now announce “Copy” more clearly, improving clarity for assistive technology users. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3324b4d598 |
fix: improve project URL and keys copy button accessibility (#47681)
## Problem The _Copy_ button is difficult to understand for screen reader users: - They don't know what it copies - They have no clear indication about what each dropdown item does - They have no confirmation a value has been copied to their clipboard ## Solution - Make sure the button that triggers the popover has a clear label for screen readers - Make sure each item has a clear label: _Press Enter to copy ..._ - Make sure each item label changes to confirm the value has been copied ## How to test - Activate the OS VoiceOver - Navigate to a project home page - Tab to the _Copy_ button. It should announce _Copy project URL and API keys_ - Press Enter then use Arrow keys to move through the items. It should announce _Press Enter to copy_ the item label - Press Enter to copy an item. It should announce item label _Press Enter to copy_ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved clipboard copy feedback so the “copied” state now resets when the popover closes, making copy confirmations more consistent. * Enhanced accessibility for copy actions by refining screen-reader text to indicate whether an item is ready to copy (“Press Enter to copy”) or has already been copied. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
27050a69b1 | Color spot fixes policy and sheet (#47682) | ||
|
|
bac4814123 |
fix(logs): color regressions from design system update (#47676)
## Summary - Fix unreadable "Large ranges may result in memory errors" warning text in the Logs date picker — a stray `text-warning-foreground` class (dark ink) was winning over `text-warning` on the dark `bg-warning-300` fill. - Fix "Search collections..." sidebar wrapper background mismatch — `bg-background-200` now resolves to the elevated `--card` surface instead of `--background`, so it no longer matches the sidebar's `bg-dash-sidebar`. - Fix the Unified Logs "Live" toggle button rendering blue text instead of white when active — a leftover `border-info text-info` override was fighting the `primary` variant's own text color, now that `--info` resolves to a more distinct blue. All three are contrast/color regressions surfaced by the recent design-system color token changes. ## Test plan - [ ] Open a project's Logs Explorer, pick a large date range, confirm the warning text is readable - [ ] Check the Logs sidebar "Search collections..." box background matches the rest of the sidebar in both light and dark mode - [ ] Toggle "Live" mode in Unified Logs and confirm the button text is white/legible on the green background <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the large-range warning banner appearance in Logs settings. * Refined the Logs sidebar header background styling for a more consistent look. * Simplified the DataTable live button styling behavior by removing conditional class composition while preserving the existing live-mode visuals. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8f69cfaaae |
fix: add an accessible text to the organization dashboard link (#47672)
## Problem People using screen readers can't find how to navigate back to the organization dashboard. ## Solution - Add an invisible label for screen readers - Add a tooltip for all users <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a tooltip to the home navigation icon on hover (“Back to organization home”). * Enhanced app layout dropdowns to accept custom trigger content, improving accessibility with updated labels for branches, organizations, and projects. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
34d641f50b | feat(pipelines): Add clarification on region (#47641) | ||
|
|
484726a45c |
fix(studio): warning colours broken in light mode after colour migration (#47660)
## What kind of change does this PR introduce? UI bug fix ## What is the current behavior? After the colour system migration (#47288), `--warning-default` was removed in light mode in favour of the semantic `--warning` token. Several studio call sites still referenced `hsl(var(--warning-default))`, which resolves to an invalid colour in light mode. This caused warning segments in stacked bar charts (e.g. Realtime on project overview v2) to render black instead of amber, with missing tooltip swatches. The colour appeared to "fix itself" on hover because the dimmed state used `--warning-500`, which is still defined. ## What is the new behaviour? Studio consumers that referenced the removed token now point at tokens that still resolve in light mode. Chart warnings use new app-level `--chart-warning` / `--chart-warning-muted` variables (stepped scale, theme-aware) rather than the removed `--warning-default`. We only update **Studio app consumers** that were still calling the old token: - `LogsBarChart` → `--chart-warning` tokens - `apps/studio/styles/globals.css` → defines those chart tokens + fixes `--sidebar-primary-foreground` - A handful of chart/tooltip call sites in Studio (`EdgeFunctionOverview`, `UnifiedLogs`, etc.) - Table editor dirty cell text → `--warning-600` (still on the stepped scale) ## To test Use a hosted project that already has warnings on project home (e.g. Realtime with a non-zero warnings count). Switch Studio to **light mode**. 1. Open **Project home** (`newHomepageUsageDeltas` flag enabled). 2. Find a service card with warnings in **Project usage**. 3. Confirm warning bar segments are amber/orange (not black), tooltip swatches show amber, and hover does not flip them black. 4. Quick dark mode sanity check. Should look unchanged. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Standardized warning-series and highlight colors across charts, logs, countdown timers, and interface indicators using the shared theme tokens (`--chart-warning` / `--chart-warning-muted`). * Refreshed warning-related theme wiring for both light and dark modes, including sidebar foreground color. * **Bug Fixes** * Updated “dirty” table cell text color to align with the revised warning palette. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
568a26899a |
fix: catch permission errors when querying integrations data (#47272)
Previously, uncaught permission errors were bubbling up and preventing the marketplace UI from rendering at all. This is a problem because users might have access to the integrations tab, but not permissions to view all the connected resources on a particular integration. In that scenario, we want to degrade gracefully and show them only those resources they have access to. |
||
|
|
ceff7b99bf |
fix(logs): guard chart query against unparseable timestamp params (#47485)
## Problem The per-service logs pages (e.g. `/project/[ref]/logs/auth-logs`) crashed with `RangeError: Invalid time value` (Sentry issue 7580074952). `calcChartStart` guarded `iso_timestamp_start` only against falsy values, so a truthy-but-unparseable timestamp (a malformed value in the URL query params) produced an Invalid Date, which propagated through `.add()` and threw when `startOffset.toISOString()` was called. The bug is on the legacy (non-OTEL) chart query path. The OTEL bucket helper had the same unguarded pattern; it did not crash but could skew the chart bucket size. ## Fix Validate parsed timestamps with `dayjs().isValid()` and fall back to now, matching the existing empty-param behavior. Applied to both `calcChartStart` (legacy) and `otelChartTruncFn` (OTEL). - Valid params produce identical output (existing tests unaffected) - Empty params still fall back to now - Malformed input no longer throws Added regression tests to `Logs.utils.test.ts` and `Logs.utils.otel.test.ts`. ## How to test - Run the logs unit tests: `pnpm test:studio` (or target `Logs.utils.test.ts` and `Logs.utils.otel.test.ts`) - In the dashboard, open a service logs page with a malformed timestamp in the URL, e.g. `/project/<ref>/logs/auth-logs?its=not-a-date` - Expected result: the page renders without crashing and the chart falls back to the default (now-based) time range <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved log chart time-range handling by safely resolving missing or invalid ISO timestamps via a shared timestamp resolver. * Updated chart bucketing and timestamp conflict logic to use the resolved endpoints, preventing errors and ensuring correct fallback granularity (including minute-level bucketing when needed). * **Tests** * Added regression coverage to confirm chart query generation (including OTEL queries) does not throw for unparseable start/end timestamps. * Verified fallback behavior to minute-level bucketing and non-throwing behavior for timestamp conflict handling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
32798c3162 |
[FE-3423] chore(studio): flag pages/** edits to mirror into TanStack routes (#47650)
Adds a PR-time reminder to mirror any edit to `apps/studio/pages/**` into the corresponding `apps/studio/routes/**` file, since the Next.js pages router and the TanStack Start route tree ship side-by-side during the migration and can silently drift. **Added:** - A CodeRabbit `path_instructions` rule (`.coderabbit.yaml`) scoped to `apps/studio/pages/**` that prompts authors to check whether a page change needs mirroring into `routes/**`. It encodes the migration's nuance so it isn't noise — pure body edits on re-export (Path A) pages propagate automatically, but layout/`getLayout`, `staticData` props, `withAuth`, redirect-path, or new-page changes must be mirrored by hand. Framed as verify-not-block, and explicitly tells authors *not* to delete the `pages/**` file. **Changed:** - `apps/studio/TANSTACK_MIGRATION.md` — documents the guardrail under the Runtime model section, and adds a cleanup-checklist line to remove it once `pages/**` is deleted (FE-3106). This is temporary scaffolding — it comes out with the final `pages/**` cleanup pass. ## To test - This needs to land on `master` first, then open a throwaway PR that touches a file under `apps/studio/pages/**` and confirm CodeRabbit leaves the reminder comment. - `path_instructions` can be flaky — if CodeRabbit doesn't fire reliably, the fallback is a GitHub Action + sticky PR comment scoped to `paths: ['apps/studio/pages/**']`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added migration guidance for Studio page changes to help keep mirrored routes in sync during the transition period. * Clarified when page updates need to be reflected in the matching route files, including new pages and changes to layout, access control, titles, static data, or paths. * Added a cleanup reminder for removing the temporary review guidance once the migration is complete. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
4a18670367 |
[FE-2417] fix(studio): update disk EBS UI copy to match new limits (#47646)
Updates the dashboard disk-management copy to match the new AWS EBS modification limits (already reflected in the docs): from the old fixed "4-hour cooldown / once every 4 hours" framing to "up to 4 modifications within a rolling 24-hour window". This is a copy-only change plus one small logic-constant alignment. Timer/countdown behavior is unchanged — this only updates wording to bring the dashboard in line with the docs. **Changed:** - `DiskSpaceBar` autoscaling tooltip, `DiskCountdownRadial` card, `DiskSizeConfiguration` "Importing a lot of data?" alert, `DiskSizeConfigurationModal` alert title + both countdown branches, `DiskManagementReviewAndSubmitDialog` IOPS + disk-size row descriptions, and two code comments — all reworded to the new "4 per rolling 24-hour window" framing - `DiskSizeConfigurationModal` countdown now derives from the shared `COOLDOWN_DURATION` constant (4h) instead of a stale hardcoded `6 * 60` (6h), so the legacy resize path matches the newer disk-attributes path ## To test - Open a Pro AWS project → **Settings → Compute and Disk** → hover the **Autoscaling** pill on the disk bar: tooltip should read "…limited to 4 within a rolling 24-hour window" (no "once every 4 hours") - Change IOPS only → **Review changes** → IOPS row description shows the new "rolling 24-hour window… as soon as the previous one completes" copy - Change disk size → **Review changes** → Disk size row shows "You can modify disk attributes up to 4 times within a rolling 24-hour window" (not "For 4 hours after changes…") - On a non-AWS Pro project → **Database → Settings → Increase disk size**: modal title reads "Disk modifications are limited to 4 per rolling 24-hour window"; any "resize again in ~X" countdown is bounded by 4 hours, not 6 - Sanity: none of the old "4-hour cooldown" / "once every 4 hours" strings appear anywhere in the disk UI <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated disk resizing messages across the app to reflect a rolling 24-hour limit instead of a fixed 4-hour cooldown. * Clarified when disk size, IOPS, and throughput changes are available again, including more accurate next-available timing. * Improved warning copy in disk configuration and review dialogs so limit messages are consistent and easier to understand. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
7b02aa2f0d |
fix: allow pausing branch projects again (#47636)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (regression). ## What is the current behavior? #44172 replaced the old `isAwsK8s`-based check with an entitlement-based check (`useCheckEntitlements('project_pausing', ...)`) for the pause project button. In doing so, it also introduced an explicit `isBranch` condition that unconditionally disables the pause button and shows "Branch projects cannot be paused" for any branch project. Prior to #44172, branches were exempt from the paid-plan pause restriction entirely — the old `isPaidAndNotAwsK8s` computation (`!isBranch && !isFreePlan && !isAwsK8s`) evaluated to `false` whenever `isBranch` was `true`, so branch projects were never blocked by that check. The new code changed this exemption into a hard block, which is the regression: branches can no longer be paused at all. ## What is the new behavior? Restore the original exemption: branch projects bypass the `project_pausing` entitlement check (as they did the old AWS K8s check), instead of being unconditionally blocked. The pause button and tooltip for branches now only take into account permissions, project status, and whether the project is active — matching pre-#44172 behavior. ```tsx const buttonDisabled = (!isBranch && !projectPausingAllowedInOrg) || project === undefined || isPaused || !canPauseProject || !isProjectActive ``` ## Additional context Regression introduced in https://github.com/supabase/supabase/pull/44172. --- _Generated by [Claude Code](https://claude.ai/code/session_01VdtDMaXzz8zgqQHSMbtMAA)_ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated project pause availability so the button now reflects the correct conditions for branch and non-branch projects. * Improved pause-related tooltips to show more accurate messaging based on plan type and project status, including when pausing may not be available on free plans. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
c87f673c4c |
Fix: improve accessibility for icon buttons (database menu) (#47531)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (accessibility improvement) ## What is the current behavior? Icon-only buttons do not have explicit accessible names for screen readers or tooltips. ## What is the new behavior? All icon-only buttons now have explicit accessible names using visually hidden text (sr-only), ensuring proper screen reader support. ## Additional context Tooltip text is preserved or added for visual users. No visual changes were introduced. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Tightened end-to-end checks for policy creation so policy names must match exactly in the list. * Improved validation coverage for SELECT, INSERT, UPDATE, and DELETE policy flows, reducing the chance of false-positive test matches. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
623a9230bd |
fix: add labels to org home page view buttons (#47633)
## Problem The buttons on the organization home page that allow to switch between list and grid views are not accessible. ## Solution Add screen readers only text to these buttons. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary of changes * **Bug Fixes / Improvements** * Improved accessibility for project view toggle controls and the clear-search action. * Added an explicit accessible label to the clear button. * Added screen-reader text and tooltips to better communicate grid vs. list view. * **Other** * Improved error handling robustness when updating report snippet visibility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
93f83651ee |
chore(studio): hide wal2json from extensions list (#47643)
## What kind of change does this PR introduce? Adds `'wal2json'` to `HIDDEN_EXTENSIONS` so it's filtered out of the extensions list in the Dashboard, matching how other non-user-facing extensions (e.g. `pg_stat_monitor`, `supautils`) are already hidden. ## Summary by CodeRabbit * **Bug Fixes** * Updated the list of hidden database extensions so `wal2json` no longer appears in places where hidden extensions are excluded. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
61f71c8b1e |
fix: remove any from report snippet model (#47644)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Minor remove any to fix ratchet baseline rules <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved error handling when making a report snippet public, so error messages are only shown when a valid error message is available. * Reduced the chance of unexpected failures from non-standard error values during this action. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d7ad603e40 |
fix(studio): fixing table editor column header background (#47585)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (Fixes #47562) ## What is the current behavior? Header and data row overlaps: <img width="1416" height="58" alt="Screenshot 2026-07-03 at 12 39 43 PM" src="https://github.com/user-attachments/assets/fd5ab174-f18d-4f84-9158-5824f43d5ab5" /> ## What is the new behavior? Now it correctly displays entry data without overlapping text: <img width="1289" height="115" alt="Screenshot 2026-07-03 at 12 38 38 PM" src="https://github.com/user-attachments/assets/df0d96d6-1091-4be9-be44-cad317b87847" /> ## Additional context Colors are consistent with surrounding for all color theme. This issue appeared after PR #47288, I am not exactly sure about the whole situation as 47288 is a massive PR. I drilled in a bit into the CSS with the help of my cursor agent, it mentioned css conflicts with react-data-grid's background-color: inherit, take it with a grain of salt though. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the grid header appearance to better match the app canvas. * Header rows now keep their existing behavior and borders, while header cells use the canvas background for a cleaner look. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cabe14e5ca |
chore: remove _Shadcn_ suffix from ui tabs components (#47628)
## Problem Now that we migrated all usages of the deprecated `Tabs` component, we don't need the `_Shadcn_` suffix anymore. ## Solution Remove `_Shadcn_` suffix from `ui` tabs components. That's all this PR does, no visual nor functional changes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Standardized tab components across the app so pages and dialogs now use the same consistent tab UI. * Improved tab-based views in design, docs, studio, learn, and website experiences for a more uniform interface. * **Chores** * Updated shared UI exports to expose tab components directly, simplifying future usage across the product. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
38669218ac |
fix: preserve copy (#47607)
- closes https://github.com/supabase/supabase/issues/47606 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Copying cell values now preserves `false` and `0` instead of treating them like empty values. * Clipboard copy behavior now only returns blank for truly empty inputs, helping keep table data accurate when copied. * **Tests** * Added end-to-end coverage for copying table cells with `false`, `0`, and `true` values. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
27c1850a9a |
feat(logs): enforce a LIMIT clause in the log explorer (#47630)
## What Enforces a `LIMIT` clause on Logs Explorer queries, replacing the previous soft warning. - Queries without a `LIMIT <n>` can no longer be run. - Instead of the warning badge, the results box shows a clear "Add a LIMIT to your query" message. - The error clears as soon as a valid `LIMIT` is added. ## Why Unbounded queries can scan very large amounts of data. This adds a UI guardrail so a bounded result set is always requested. ## Notes - New `checkForLimitClause` util detects `LIMIT <n>` outside of string literals and comments (mirrors the existing WITH/ILIKE checks), with unit tests. - The missing-limit message reuses the existing error-rendering path via a `missingLimit` reason, alongside `resourcesExceeded`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Log queries now require a `LIMIT` clause before they can run. * A new on-screen message guides users to add a `LIMIT` when it’s missing. * **Bug Fixes** * Improved log query validation to better detect valid `LIMIT` usage, including mixed case, multiline queries, and avoidance of false matches in comments, strings, or column names. * Existing error messages continue to appear for other query limits and failures. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
6770f1a148 |
feat(studio): share report snippets with the team when added to homepage report FE-3800 (#47629)
## Problem
Adding a private SQL snippet ('user' visibility) as a Home / project
overview report created a broken experience for other project members,
who saw "SQL snippet not found" because they had no access to the
snippet.
## Fix
Selecting a private snippet from the report block picker now shows a
confirmation step that makes the snippet public to the project before it
is added. Already-shared snippets are added directly, and snippets
created via drag-and-drop onto the report are now shared on creation.
## How to test
- Open a project's homepage and go to the Reports section
- Create a private SQL snippet if you do not have one
- Click "Add block" and select the private snippet
- Confirm a dialog appears explaining the snippet will become visible to
the team
- Confirm, and verify the block is added to the report
- Log in as another project member and confirm the report block renders
instead of "SQL snippet not found"
- Selecting an already-shared snippet should add it without the
confirmation dialog
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added a “make snippet public” confirmation flow for user-owned report
blocks.
* Updated snippet selection to support a private-snippet share prompt
when appropriate.
* **Bug Fixes**
* Improved duplicate-block handling to prevent adding the same snippet
multiple times.
* **Refactor**
* Refactored SQL snippet upsert payload construction for more consistent
project visibility updates.
* **Tests**
* Added unit tests covering snippet selection decision logic.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
|
||
|
|
4129c8954d |
feat(studio): TanStack project routes — auth/logs/settings/functions (stack 5.2/6, from #46424) (#47118)
**Stack 5.2/6** of the TanStack Start migration (#46424) — second half of the project routes (S5 was split for CodeRabbit's 150-file cap). Stacked on **#47117** (5.1). > [!NOTE] > Same shape as 5.1 — thin route wrappers over the existing pages-router components. With this PR every route is present, so `routeTree.gen.ts` is now **byte-identical to the migration branch**. ## What's in this PR - **Remaining project routes:** auth, logs, settings, observability, functions, advisors, project-level integrations. - **Supporting edits:** hoist `EdgeFunctionsIndexPageWrapper` out of `getLayout`, `functions/secrets`, and move `DefaultLayout` to the root for the logs page. - `routeTree.gen.ts` regenerated for the full set. ## Verification On top of S1–5.1: `studio` typecheck ✓, lint (0 errors) ✓, **Next build ✓ (181/181 pages)**. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Reorganized internal routing and page structure to improve navigation and maintainability across project settings, logs, functions, authentication, integrations, and observability sections. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
f6fc6ceb59 |
[bot] Decrease ESLint ratchet baselines (#47611)
Automated weekly decrease of ESLint ratchet baselines. Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> |
||
|
|
46b31eb53a |
[FE-3379] feat(studio): warn when db passwords need percent-encoding (#47564)
Users who set a database password with special characters (\`@\`, \`#\`, \`%\`, \`+\`, etc.) get no warning that it must be percent-encoded when used in a connection URL, which leads to confusing connection failures ([FE-3379](https://linear.app/supabase/issue/FE-3379)). <img width="700" height="200" alt="Screenshot 2026-07-03 at 6 26 43 PM" src="https://github.com/user-attachments/assets/48608d65-8057-4abe-96fc-c0ede3550951" /> <img width="1002" height="395" alt="Screenshot 2026-07-03 at 6 27 14 PM" src="https://github.com/user-attachments/assets/1366b985-7d80-4e7d-97f0-c79d5c84cefd" /> <img width="548" height="303" alt="Screenshot 2026-07-03 at 6 27 26 PM" src="https://github.com/user-attachments/assets/b042101a-0e88-4730-adb8-1b490018f208" /> **Changed:** - `PasswordStrengthBar` now shows a warning-colored callout (with a docs link) whenever the entered password contains characters that need percent-encoding — this covers project creation, reset database password, restore-to-new-project, and the Vercel deploy-button flow - Replaced `DATABASE_PASSWORD_REGEX` (only caught `@`, `:`, `/`) with a `passwordNeedsPercentEncoding()` helper based on `encodeURIComponent`, so `#`, `%`, `+`, `?`, `&`, spaces etc. are caught too - Moved `SpecialSymbolsCallout` from `ProjectCreation/` to `components/ui/` since it's now shared **Added:** - Info admonition in the Connect sheet next to connection strings that still contain `[YOUR-PASSWORD]` (direct connection + `.env`-based file setups; hidden for psql and .NET where percent-encoding doesn't apply, and after a password reset since the substituted password is already encoded) ## To test - Project creation → type a password containing \`#\` or \`@\` → warning callout appears above the strength bar; disappears for alphanumeric passwords - Database Settings → Reset database password → same behaviour - Connect sheet → Direct connection → note shows under the connection string for URI/JDBC types, not for psql; after resetting the password from the sheet, the note disappears (password is substituted already encoded) - Connect sheet → Node.js/Python/Go/SQLAlchemy file setups show the note; .NET does not - \`pnpm vitest run lib/password-strength.test.ts\` passes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Added a dedicated password encoding note (with documentation link) on direct connection screens when the password is embedded in a URL. * Added an encoding hint to the password strength area when percent-encoding is required. * **Bug Fixes** * Removed regex-based “invalid password” callout and replaced it with safer percent-encoding detection logic. * **Tests** * Added test coverage for `passwordNeedsPercentEncoding`. * Removed obsolete Project Creation password regex tests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
09ea558d54 |
Vercel install layout (#47550)
Bring the Vercel install layout up to date with other connect screens. Resolves DEPR-615. | Before | After | | --- | --- | | <img width="1600" height="1200" alt="CleanShot 2026-07-03 at 10 51 59@2x" src="https://github.com/user-attachments/assets/6a8c2910-8c45-4c7d-8d38-8b80c5cf4c83" /> | <img width="1150" height="1318" alt="CleanShot 2026-07-03 at 11 56 17@2x" src="https://github.com/user-attachments/assets/3a5add5c-fea4-44f3-a368-5732257b27d9" /> | ## Testing - Open the deploy preview or staging URL for `/dashboard/integrations/vercel/install` with callback params from a real Vercel Marketplace install redirect (see _Vercel_ subheading below). - Confirm the install screen renders with the selected Supabase account, organization picker, and primary install CTA. - Remove required callback params such as `code`, `configurationId`, or `source` to verify the "Missing Vercel installation details" warning state. - Clicking "Install integration" with an expired or reused `code` can show `Creating Vercel integration failed: Failed to get Vercel access token`; that is expected for preview UI validation. A full successful install requires a fresh Vercel-generated code from the install flow. To reiterate; this won’t work because the code will be invalid. But it should show that everything is hooked up right for prod. ### Vercel 1. Go to Supabase. Open either org-level or project (settings) level integrations. 2. Tap "[Install Vercel Integration](https://vercel.com/integrations/supabase-local)". 3. Follow the install instructions from that Vercel page. This should open a browser window. 4. Copy the URL of that browser window. Take the params and paste them instead at the end of the deploy preview URL. Example of #4: ```txt Before: https://supabase.com/dashboard/integrations/vercel/install?code=jDhIBDlD58zzLVtuSNjJpUSu&configurationId=icfg_v3dKllQIniSOwdVI3gypnZh3&next=https%3A%2F%2Fvercel.com%2Ftest-5706s-projects%2F~%2Fintegrations%2Ficfg_v3dKllQIniSOwdVI3gypnZh3%2Finstalled&source=marketplace&teamId=team_mPkGQZjTLBEUXh15b03iVsTg After https://studio-staging-git-chore-install-layout-supabase.vercel.app/dashboard/integrations/vercel/install?code=jDhIBDlD58zzLVtuSNjJpUSu&configurationId=icfg_v3dKllQIniSOwdVI3gypnZh3&next=https%3A%2F%2Fvercel.com%2Ftest-5706s-projects%2F~%2Fintegrations%2Ficfg_v3dKllQIniSOwdVI3gypnZh3%2Finstalled&source=marketplace&teamId=team_mPkGQZjTLBEUXh15b03iVsTg ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Updated the installation experience with a cleaner, more guided layout. * Added clearer organization selection during setup, including visibility into which organizations are already installed. * **Bug Fixes** * Improved loading and error handling during installation. * Added clearer warnings for missing setup details, already-installed integrations, and cases with no available organizations. * Fixed routing behavior so organization selection is preserved more reliably. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
5c3d250140 |
docs: clarify that creating new API keys does not disable legacy keys (#47395)
Creating publishable and secret keys adds them alongside the existing anon and service_role keys without affecting them. Make this explicit in two places so users don't assume their legacy keys are revoked: - Add an Admonition note to the API keys guide explaining both key types work simultaneously and legacy keys must be disabled in a separate step. - Update the "Create new API keys" dialog in Studio to reassure users that their existing anon and service_role keys remain valid. |
||
|
|
61078d2617 |
chore(studio): add jsx-a11y ESLint ratchet rules for statically-detectable a11y issues (#47582)
## Summary - Follow-up to the axe-core accessibility audit (FE-3781), which found 1,733 failing elements across 126 Studio surfaces deduplicating to 12 root-cause families. A subset of those (missing accessible names/labels, invalid/redundant ARIA, empty headings/anchors) is statically detectable — this adds ESLint coverage for it instead of relying solely on the runtime axe-core CI gate. - Adds 13 `jsx-a11y` rules to `apps/studio/eslint.config.cjs` at `'warn'`: `aria-props`, `aria-proptypes`, `role-supports-aria-props`, `anchor-has-content`, `control-has-associated-label` (`controlComponents: ['Button', 'Switch']`), `label-has-associated-control` (`labelComponents: ['Label']`, `controlComponents: ['Input', 'Switch']`), `aria-role`, `no-redundant-roles`, `no-aria-hidden-on-focusable`, `tabindex-no-positive`, `anchor-is-valid`, `heading-has-content`, `no-distracting-elements`. - Wires all 13 into the existing `lint:ratchet` script and initializes their baselines in `apps/studio/.github/eslint-rule-baselines.json`, so any *new* violation fails `studio-lint-ratchet.yml` while the pre-existing ones (mostly `control-has-associated-label`: 274, `label-has-associated-control`: 37) are tracked and shrink over time via the weekly baseline-decrease cron. Resolves [FE-3795](https://linear.app/supabase/issue/FE-3795/add-jsx-a11y-eslint-ratchet-rules-for-statically-detectable-a11y). ## Test plan - [x] `pnpm --filter studio run lint:ratchet` passes (exit 0, no regressions) - [x] Spot-checked several flagged instances against source to confirm true positives (e.g. an unlabeled save/cancel icon-button pair in `AIAssistantChatSelector.tsx`, an empty `<h3>` in `PITRForm.tsx`) - [x] CI (`studio-lint-ratchet.yml`, typecheck.yml lint step) green on this PR <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Expanded Studio’s accessibility linting to cover additional ARIA prop validation, label/control relationships, anchor/heading validity, role/ARIA correctness, and focus/tab behavior (including distracting markup). * Updated accessibility lint baselines so tracked violations remain accurate as rules expand. * **New Features** * Enhanced the Studio lint “ratchet” workflow to load ratchet rule IDs from an external `rules-file` instead of a long inline command. * **Tests** * Added an integration test to verify rule IDs are read from the `rules-file`. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
514c3aa0d0 | fix(self-hosted): type generation should respect exposed schemas (#47577) | ||
|
|
e144628515 |
fix: studio observability sticky nav background is wrong (#47574)
## Problem Only in dark mode <img width="1003" height="324" alt="image" src="https://github.com/user-attachments/assets/e131fd07-1327-4a0b-bb27-eccf1f5d7f93" /> ## Solution <img width="943" height="230" alt="image" src="https://github.com/user-attachments/assets/bcbee6e6-d303-45c6-b612-eb0f0423d458" /> |
||
|
|
7d3f72ec7d |
feat(studio): TanStack project routes — data surfaces (stack 5.1/6, from #46424) (#47117)
**Stack 5.1/6** of the TanStack Start migration (#46424). The original S5 (174 files) was over CodeRabbit's 150-file review cap, so it's split into 5.1 + 5.2 by product. Stacked on **#47113** (S4). > [!NOTE] > Thin route wrappers rendering the existing pages-router components via compat shims. Next-safe (full Next build run). The TanStack app isn't functional end-to-end until 5.2 + the matrix flip. ## What's in this PR - **Data-cluster project routes:** database, editor, sql, storage, realtime, branches. - **Top-level / onboarding routes:** `authorize`, `join`, `logout`, `redeem`, `verify-email`, `claim-project`, aws-marketplace, Vercel/GitHub integration entrypoints; `_app`/`_auth` layout shells; `/org/_` + `/project/_` catch-alls. - **Supporting edits:** hoist `BranchesPageWrapper` out of `getLayout`, `ConnectStepsSection` `import.meta.glob`, `api/server.js`. - `routeTree.gen.ts` regenerated for the routes present so far. ## Verification On top of S1–S4: `studio` typecheck ✓, lint (0 errors) ✓, **Next build ✓ (181/181 pages)**. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Restructured application routing infrastructure for improved code organization and maintainability. * Extracted and refactored layout wrapper components for enhanced reusability across different sections of the application. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
6134e67693 |
fix: limit command menu height in auth observability filter (#47572)
## Problem We don't limit command menu height by default because we usually don't have that many options. It's an issue here as shown in the screenshot because it hides the _Apply_ button ## Solution Add a max height to the list of options Before: <img width="1331" height="1019" alt="image" src="https://github.com/user-attachments/assets/512b26ca-c08b-44c5-8bed-c89d5ab87da3" /> After: <img width="1217" height="828" alt="image" src="https://github.com/user-attachments/assets/43a4066d-7b20-4615-81ec-cebdb8539ec1" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Adjusted the reports filter dropdown to limit its height, making long lists easier to browse and preventing the menu from growing too large on screen. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |